Description
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
Remediation
References
https://hackerone.com/reports/319576
Related Vulnerabilities
CVE-2020-10199 Vulnerability in maven package org.sonatype.nexus:nexus-extdirect
CVE-2022-2900 Vulnerability in npm package parse-url
CVE-2020-15999 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-24122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-12395 Vulnerability in maven package us.dynmap:dynmap